Investigate the anomaly
Open the anomaly
Open the anomaly and start an investigation:
- Select Anomalies () from the navigation menu.
- Find the service showing as Anomalous.
- Select Investigate (or View Investigation if a Canvas investigation is already underway).
Compare the chart against the typical range
On the service’s Error Rate view, locate the shaded typical range band on the chart.
Compare the current value against that band, and note whether the deviation is a single spike or a sustained shift.
Review the anomaly history
In the Anomalies section of the service’s detail page, review anomalies detected in the current time range.
Select a wider time range, such as 30 days, to see whether this is a recurring pattern for the service or a first occurrence.
Check the Canvas investigation
If auto-investigate is turned on for the service, open the Canvas investigation that started automatically and review its likely cause.
If a Slack channel is configured as a recipient, check that channel too since Canvas joins the thread with its findings.If auto-investigate isn’t turned on, select Run Query from the chart to open the underlying query in Query Builder, then run BubbleUp against the anomalous period.
Make the call
With the chart, history, and investigation findings in hand, you have what you need to decide how to respond:- If the deviation is sustained, affects a large share of traffic, or matches a known incident pattern, escalate to the configured recipients and continue the investigation in Canvas or Query Builder.
- If the deviation is a brief spike, isolated to a small slice of traffic, or explained by a known deploy or maintenance window, you can close the investigation with confidence rather than escalating further.